Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -2 articles for you...
81

Postini Report Reveals 91% of Emails Classified as Spam Amid Surge

No, you're not imagining things. You have been getting a lot of spam lately. That's because digital miscreants are using contaminated images and stealthy malware to unleash unsolicited email at unprecedented levels, according to new research from San Carlos, Calif.-based Postini Inc. and UK-based Sophos. Attackers use these tactics to hijack computers and turn them into spam relays, often without the user's knowledge. "Bot activity is the major driver here," said Daniel Druker, Postini's executive vice president of marketing. "Bot-infected machines become part of these zombie PC armies that are used to push out spam." . Postini has watched spam levels spike by nearly 60% in the last eight weeks, and Druker said 91% of all email is now spam. Over the past 12 months, the daily volume of spam rose by 120%, he added. Postini monitors 10 million users across 36,000 businesses worldwide. Of that number, the average user gets seven wanted emails a day, while Postini blocks 77 unwanted emails a day. "That's for the average user," he said. "This is an all-time high, and it shows that spammers are increasingly aggressive and sophisticated in their techniques." The link for this article located at Tech Target is no longer available. . EmailProtect has revealed a shocking 65% surge in junk messages, leading to 92% of all correspondence being deemed as unsolicited.. spam levels,email tactics,botnet attacks,email security,cyber threat. . LinuxSecurity.com Team

Calendar%202 Nov 09, 2006 User Avatar LinuxSecurity.com Team Privacy
78

Effective Strategies Against Spam: Anti-Virus Companies and Email Growth

Since I have little hope for the Anti-Virus industry and really doubt they will take the logical course of action and reconfigure their inferior products, it's probably best if I recommend another course of action. Every time you receive a piece of mail from an Anti-Virus company product, treat it like any other spam. Forward it to the appropriate abuse/postmaster contacts of the remote system. Make sure you also send a copy to their upstream provider and any law enforcement that is appropriate. Be sure to send a copy to the offending spammer/Anti-Virus company so they are aware you don't like their practice. . . .. No one can argue that the spam problem is getting better. Despite advances in anti-spam technology and legislation against spam, unwanted junk mail is flowing into our inboxes at an increased rate. Stock tips, enhancement drugs, Nigerian scams, DVD copy software and hundreds of other products or services get shoved in our face. For roughly three years, the Internet has seen worms that spread via e-mail, often taking addresses out of the infected machine's web cache, user addressbook or other sources. Some of these worms will also forge/spoof the "From:" line so the mail appears to be from someone else, in an attempt to make the mail more 'trusted'. To be clear, here is a sample timeline of how these work: 1. EvilGuy01 writes and releases a new worm. 2. Fred is a moron and clicks on an attachment from a stranger, infecting his machine. 3. The worm mails a copy of itself to everyone in Fred's addressbook. 4. The mail sent out spoofs the headers of the mail so it may be "From: George" or "From: Sally". 5. Tom gets a copy of the mail "From: Sally" and clicks on the attachment, infecting himself. 6. Tom sends mail to Sally complaining about her evil shenanigans. 7. Sally replies to Tom with "d00d WTF?! lol" since she never sent the mail. The concept is very simple, and extremely effective. Anti-Virus companies are well aware of this trait present in many "mm" (Mass Mailing) worms. Reading throughtheir descriptions, they document each worm that spreads itself in this fashion. Looking at one example on the McAfee site: W32/Mydoom@MM generates emails with a spoofed From: field, so incoming messages may appear to be from people you know. Furthermore, the subject line and message body are both randomly generated by the worm. Each of these Anti-Virus or mail gateway companies tend to configure their products to do the same thing. If a piece of mail comes in with a known virus, trojan, worm or taboo attachment, it will stop the mail from reaching the intended recipient, notify the administrator, and either quarantine or delete the hostile content. Simple and effective. However, each of these companies also has their product mail the person who sent in the hostile content saying "You are infected" in so many words. While such intentions are noble, think about the reality of what is happening. For over three years, these worms that forge the "From:" address have been sending out millions of mail attempting to propogate themselves. For each of these mails that reach an Anti-Virus product or gateway, they get blocked and replied to.. based on that forged "From:" line. Result? Millions more e-mails are sent out to innocent people that never sent the mail in the first place. The link for this article located at attrition.org is no longer available. . The problem of spam continues to thrive, notwithstanding improvements in anti-spam technologies. Explore the role that anti-virus firms play in exacerbating the prevalence of email spam.. Spam Management, Email Security, Anti-Virus Issues, Internet Threat Mitigation, Email Tactics. . LinuxSecurity.com Team

Calendar%202 Jan 29, 2004 User Avatar LinuxSecurity.com Team Vendors/Products
81

Survey on Spammers Ignoring Laws and Covert Tracking Methods

Many spammers are ignoring laws forbidding them to insert covert tracking codes in their messages, according to a survey by out-law.com, the IT and ecommerce legal service arm of law firm Masons, and network security outfit iomart. The survey highlights . . . . Many spammers are ignoring laws forbidding them to insert covert tracking codes in their messages, according to a survey by out-law.com, the IT and ecommerce legal service arm of law firm Masons, and network security outfit iomart. The survey highlights how spam messages often contain covert tracking codes which enable senders to record and log recipients' email addresses as soon as they open a message. Such spamming techniques, often used by spammers to identify active accounts, are well known. Although iomart's investigation yields a little more insight into this (more anon), we'll draw your attention first to Masons' assessment of the effectiveness of laws on unsolicited commercial email. . Many spammers are ignoring laws forbidding them to insert covert tracking codes in their messages, a. spammers, ignoring, forbidding, insert, covert, tracking, codes, their, messages. . LinuxSecurity.com Team

Calendar%202 Feb 12, 2003 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200